Skip to content
Benchmarks

redact-secret · Report

Unclassified assignment literal

Arbitrary literal in a sensitive-looking assignment, masked as project policy rather than a provider format.

  • Not provider-specific
  • Detectors: generic-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT3 · Project policy
  • Dossier researched2026-09-26

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-26

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-26 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

  • Provider documented · mutable-property-source · current · observed 2026-09-20

    Documentation for the one property varied in legacy twin fixtures (context-twin decision (#36)): no provider exists for an arbitrary literal. The recorded decision is that the twin keeps the value and mutates exactly one property of the assignment context; silence is project policy, never a format claim

  • Project policy · legacy-contract-tier · current · observed 2026-09-20

    The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.

    Source not recorded.

  • Project policy · dossier-research · current · observed 2026-09-26

    Legacy dossier research (verdict ready, tier T3) cited 2 sources; the dossier does not attribute sources to individual properties.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
none. An arbitrary literal (8 to 4096 bytes in core) assigned to a sensitive-looking name such as client_secret; entropy only selects confidence. RFC 6749 allows any printable ASCII (VSCHAR), RFC 8265 any PRECIS freeform string.
Basis
none possible; the family has no provider ("provider": null). The #653 hunt found no source for the scored span; masking is project policy (T3, decision 2026-09-26-qualify-bounded-t3-credential-policy, benchmarks#365, core #857), so the verdict is ready at T3, consistent with the other three policy families.
Issuance
not applicable.
Contract in core
detector-families.md; #653 record; the ADRs it cites cover the warn-on-high-signal-names policy.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
237
Left readable
35
Redacted too much
0
False alarms
1

237 fixtures: 3 expect a redaction, 122 must stay quiet, 112 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented9100
T3Project policy2123401
T0Pending review16000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it23711401
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it2376200
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped2373501
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it23711500

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
every provider family whose value sits in an assignment; a named provider detector wins.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
gitleaks · rules 8.30.1generic-api-keykeyword-before-value assignment with a literal of 10 or more characters
openredaction · rules 1.1.5GENERIC_API_KEYapi key keyword + a value of 20 or more characters
openredaction · rules 1.1.5GENERIC_SECRETpassword, passwd, pwd or secret keyword + a value of 8 or more characters
openredaction · rules 1.1.5OAUTH_CLIENT_SECRETclient secret or consumer secret keyword + 20 or more characters
openredaction · rules 1.1.5OAUTH_TOKENoauth token or access token keyword + 20 or more characters

No rule maps to this family in flare-redact, trufflehog.

237 of 237 rows

Fixtures in this family

237 rows, redact-secret's outcome on each. Rows that need a look come first (36), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Unclassified assignment literal
FixtureKind and evidenceredact-secret
generic-literal-alphabet-edge-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-standard-padded-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-standard-padded-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-standard-padded-three-layers-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-standard-unpadded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-url-safe-padded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-url-safe-unpadded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-url-safe-unpadded-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-url-safe-unpadded-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-url-safe-unpadded-of-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-base64-url-safe-unpadded-of-hex-upper-of-base64-standard-padded-in-jsonbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-hex-lower-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-hex-lower-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-hex-lower-of-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-hex-lower-of-hex-lower-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-hex-mixed-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-hex-upper-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-alphabet-edge-hex-upper-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-base64-standard-padded-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-base64-standard-padded-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-base64-standard-padded-three-layers-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-base64-url-safe-unpadded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-base64-url-safe-unpadded-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-base64-url-safe-unpadded-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-base64-url-safe-unpadded-of-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-base64-url-safe-unpadded-of-hex-upper-of-base64-standard-padded-in-jsonbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-hex-lower-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-hex-lower-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-hex-lower-of-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-hex-lower-of-hex-lower-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layersProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-hex-mixed-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-hex-upper-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
generic-literal-padding-edge-hex-upper-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-formProject policyT3 · Project policyLeft readable
state-json-output-password-with-sensitive-truehashicorp-terraform-authored · terraform-json-sensitive-attribute-literal-beside-true-flagMust redactT1 · Provider-documentedLeft readable
stdout-mask-where-source-has-environment-referencejupyter-notebook-files-authored · already-masked-valuesMust not flagT3 · Project policyFlagged
generic-literal-alphabet-edge-basebase64-hex-representation-bases · literal-secrets-under-generic-credential-namesProject policyT3 · Project policyRedacted
generic-literal-padding-edge-basebase64-hex-representation-bases · literal-secrets-under-generic-credential-namesProject policyT3 · Project policyRedacted
api-keygeneric · literal-secrets-under-generic-credential-namesProject policyT3 · Project policyRedacted
arn-accountgeneric · secret-manager-grammar-imitationsProject policyT3 · Project policyRedacted
authgeneric · nested-yaml-literal-passwordsProject policyT3 · Project policyRedacted
aws-secret-access-key-truncated-near-missgeneric · credential-named-literal-near-missProject policyT3 · Project policyRedacted
block-literalgeneric · block-yaml-and-brace-prefixed-secret-literalsProject policyT3 · Project policyRedacted
browserbase-api-key-bb-test-key-near-missgeneric · credential-named-literal-near-missProject policyT3 · Project policyRedacted
cerebras-api-key-pinecone-hyphen-key-near-missgeneric · credential-named-literal-near-missProject policyT3 · Project policyRedacted
changed-secretgeneric · aws-example-keys-one-character-offProject policyT3 · Project policyRedacted
client-secretgeneric · literal-secrets-under-generic-credential-namesProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-overlong-value-near-missgeneric · credential-named-literal-near-missProject policyT3 · Project policyRedacted
databasegeneric · nested-yaml-literal-passwordsProject policyT3 · Project policyRedacted
datadog-api-key-short-keygeneric · documented-format-literalProject policyT3 · Project policyRedacted

Sources

Researched 2026-09-26.

Documentation and code

Research log